Skip to content
Tech News
← Back to articles

Cisco warns of max severity ISE zero-day exploited in attacks

read original more articles
Why This Matters

Cisco disclosed a maximum-severity authentication bypass flaw in its widely used Identity Services Engine (ISE) and ISE-PIC products that is already being actively exploited in the wild. Since ISE is central to enforcing Zero Trust access controls across enterprise networks, this vulnerability poses a serious risk of unauthorized network access for organizations that haven't patched. The lack of workarounds means immediate patching is the only defense, making this a high-priority issue for enterprise IT and security teams.

Key Takeaways

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.

Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models.

The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.

"This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint," the company explained. "A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."

Cisco also warned customers on Wednesday to secure their systems since its Product Security Incident Response Team (PSIRT) flagged CVE-2026-76460 as actively exploited.

"The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."

Because no workarounds exist, applying the security updates is the only recommended course of action to protect networks from ongoing attacks.

Cisco ISE or ISE-PIC Release First Fixed Release 3.1 3.1 Patch 12 3.2 3.2 Patch 11 3.3 3.3 Patch 12 3.4 3.4 Patch 7 3.5 3.5 Patch 4

Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.

Admins should also cross-check firewall and network logs for signs of suspicious activity (including downloads and uploads from and to external or malicious IP addresses) because attackers may remove evidence of exploitation after obtaining command execution with root privileges.

... continue reading